CAKJU

The card game is a joke. The hiring problem is not.

A plain summary of the public record, with sources. Last reviewed 22 September 2026.

This deck exists because of a real detection trick: interviewers discovered that asking a remote candidate to say something insulting about Kim Jong Un sometimes ends the call instantly. That is funny. The reason it works is not. Here is what is actually known, what the trick is and isn't good for, and what to do instead.

~$800M Revenue the US Treasury attributed to North Korea's overseas IT worker programme in 2024.
100+ US companies infiltrated via a single pair of American facilitators, in one DOJ case.
Dozens Fortune 100 organisations that Mandiant says have unknowingly hired these workers.

What the scheme actually is

North Korea runs a large, state-directed programme that places IT workers into remote jobs at Western companies under false identities. The salaries are funnelled back to the regime, which is the point: it is a sanctions-evasion revenue operation, not primarily an espionage one. Google's Mandiant tracks the activity as UNC5267; Microsoft tracks an overlapping set as Jasper Sleet.

The mechanics are consistent across cases. A worker applies using a stolen or synthetic US identity, often with an AI-retouched profile photo. If hired, they ask for the company laptop to be shipped somewhere other than their stated address — to a laptop farm, typically a house in the US run by a paid local facilitator, who plugs the machines in and installs remote access software. The worker then connects from China or North Korea through that machine, so the company sees a domestic IP.

US prosecutors have charged both sides of this. In one case, DOJ indicted two North Korean nationals along with facilitators in the US and Mexico; in another, two US nationals were sentenced for running farms that placed workers at more than a hundred US companies, generating over $5 million for the regime. One facilitator operated out of residences in Nashville.

The case everyone cites

In July 2024, the security-awareness company KnowBe4 published an unusually candid post explaining that it had hired one of these workers as a principal software engineer — and then caught him.

The candidate cleared four video interviews and a background check. The identity was a real US person's, stolen; the photo was a stock image modified with AI to match. Suspicious activity on the new hire's workstation was flagged on 15 July, and KnowBe4 says it cut off the account's restricted onboarding access within 25 minutes. Nothing was exfiltrated.

The reason this case matters is not that KnowBe4 was careless — it is that they were careful, and it still worked. Video interviews and a background check were not enough.

Where the Kim Jong Un question came from

At the RSA Conference in San Francisco on 28 April 2025, Adam Meyers, who runs counter-adversary operations at CrowdStrike, described his preferred screening question on a panel. His version was to ask how fat Kim Jong Un is.

“They terminate the call instantly, because it’s not worth it to say something negative about that.” Adam Meyers, CrowdStrike, RSAC 2025

Founders have reported the same thing independently. Harrison Leggio, who runs the crypto startup g8keep, told Fortune that roughly 95% of the résumés he receives come from North Korean engineers posing as Americans, and that asking an applicant to say something negative about Kim Jong Un usually makes them panic and block him. A widely-shared interview recording shows a candidate asked to repeat an insult, becoming visibly uncomfortable, claiming not to understand, and leaving the call.

It works — when it works — because insulting the leader is a criminal act in North Korea with consequences that extend to the speaker's family. It is not a bluff a loyal operative can comfortably call.

Why it is not a security control

Treat the question as a curiosity, not a gate. Four reasons:

Our position

We made a party game out of this because the premise is absurd and the regime deserves the mockery. We would rather you did not run it on real candidates. If you want the laugh, buy the deck and play it at the offsite.

What actually screens for this

The published guidance from Mandiant, Microsoft, and the US agencies converges on the same short list. None of it is exotic.

During hiring

At onboarding

After hire

If you think you have hired one

Do not confront them and do not just quietly terminate. Preserve the evidence, contain the account, and report it — in the US, to the FBI via ic3.gov and to your counsel. Paying a sanctioned party creates exposure under OFAC rules independent of any security impact, so legal needs to be in the room early.

Sources

  1. How a North Korean Fake IT Worker Tried to Infiltrate UsKnowBe4, 23 July 2024.
  2. Staying a Step Ahead: Mitigating the DPRK IT Worker ThreatMandiant / Google Cloud (UNC5267).
  3. Jasper Sleet: North Korean remote IT workers' evolving tacticsMicrosoft Security, 30 June 2025.
  4. The one interview question that will protect you from North Korean fake workersThe Register, 29 April 2025 (Adam Meyers at RSAC).
  5. North Korean IT workers are spamming résumés; one founder asks them to insult Kim Jong UnFortune, 10 April 2025.
  6. Two North Korean Nationals and Three Facilitators IndictedUS Department of Justice.
  7. Two US Nationals Sentenced for Facilitating Fraudulent Remote IT Worker SchemeUS Department of Justice.
  8. How North Korean IT workers leverage AI and vulnerable AmericansCNN, 5 August 2025 (Treasury revenue figure).

Back to the card game